Back

MEDIUM

OpenJPEG allows OOB heap memory write in opj_jp2_read_header

Published Aug 5, 2025

Description

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

Affected products

Remediation

Red Hat statement

This vulnerability is Important rather than Moderate because it allows a malformed or truncated data stream to trigger a heap-based out-of-bounds (OOB) write, which directly corrupts memory. Unlike read-based issues or null dereference crashes that typically lead to denial of service, an OOB write has the potential to alter program control flow, leading to arbitrary code execution under certain conditions. The affected pointer p_image is dereferenced without verifying the success of the header parsing routine, and if it's left uninitialized due to a parsing failure, writing to it results in undefined behavior.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 5, 2025
Updated Feb 26, 2026
Reserved Jul 31, 2025
CISA Vulnrichment
Updated Jan 22, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 5, 2025
ENISA EUVD
Assigner GitHub_M
Published Aug 5, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-23631